The Loop  ·  Issue N°040

The Loop

A field journal of the AI frontier — for engineers who ship.

§ The Patch

By AI Blog Editor
Sep 26, 2026 · 20 min read

The Patch — September 26, 2026

OpenClaw's 74 new CVEs are all fixed on its main line by 2026.9.3, but 51 of them flag the extended-stable 2026.7.35 and none says whether it carries the fix.

OpenClaw picked up 74 CVEs at 03:30 UTC this morning, one for each advisory it published on September 11. This digest missed those advisories at the time. All 74 are fixed on the main line by 2026.9.3, but 51 of them flag the extended-stable 2026.7.35, and no record says whether that line carries the fix. Claude Desktop fixed an 8.5 on macOS, which matters to anyone who pushes updates by hand.

Component

Affected

Severity

Patched?

Action

Relevance

openclaw + plugins ×74

< 2026.7.1 · < 2026.8.1 · 4 up to < 2026.9.3

8.8 ×8 · 9.0 (v4, iOS app) · 38 high · 30 medium · 5 low

yes → 2026.9.3 (Sep 8); 2026.9.6 current

upgrade the main line; extended-stable 2026.7.35 is flagged by 51

AI stack

Claude Desktop (macOS)

1.1.3918 – < 1.15962.0

8.5 (v4, high)

yes → 1.15962.0

auto-update already has it; push it to managed installs

AI stack

litellm: semantic cache

< 1.101.0-rc.1

7.7 · 8.7 (v4)

yes → 1.101.0 (Sep 15); not in 1.100.3 / 1.99.4 / 1.98.1 (Sep 25)

shared proxies with semantic caching: move to 1.101.0 or later

AI stack

mcp-remote ×5, rescored

0.1.16 – 0.1.38

9.1 · 8.8 · 7.5 · 2 unscored

no fix declared; 0.14.3 current

connect only to remote MCP servers you trust

AI stack

Worth your morning

OpenClaw: the main line is clear, the extended-stable line is unclear. VulnCheck assigned the 74 CVEs to advisories that OpenClaw published on its own repository on September 11. OpenClaw's repository wasn't in this digest's sweep then; it is now. The records cover authorization gaps between owners and other senders in chat channels, exec-approval and sandbox-policy bypasses, SSRF-guard gaps and credential handling. They span the gateway and its Slack, Discord, WhatsApp, Matrix, Teams, Feishu, LINE and voice-call plugins. Every record names a main-line fix: 2026.7.1 (July 13) for 20 of them, 2026.8.1 (August 31) for 48, and 2026.8.2, 2026.9.2 or 2026.9.3 for the remaining four. Two more cover the iOS app, fixed in its 2026.8.11. The npm package gets 2.8 million downloads a week. The current release is 2026.9.6, so anything on 2026.9.3 or later clears every npm record.

OpenClaw also ships a July maintenance line under npm's extended-stable tag, currently 2026.7.35 (September 21). Its notes say the line carries "critical security updates", and one listed change, an escaped-newline command-parsing fix, matches CVE-2026-100559. No record names a 2026.7.x fixed version, though. A scanner will flag 2026.7.35 on 51 of the 74, and nothing published says which of those are real. The June maintenance release, 2026.6.35 (September 10), is flagged by 69. If you can move to the main line, do. If you need extended-stable, ask OpenClaw which of the 51 the July line carries before you close the alerts. npm audit and Dependabot will stay quiet either way. The repository advisories return 404 in GitHub's global database, and this morning's CVE records carry no package mapping.

Claude Desktop: push 1.15962.0 if you manage updates. Anthropic published GHSA-v234-4jrq-mgg6 (8.5 on v4) last night. Claude Desktop blocks file types that run code on open from being opened directly out of a Cowork session's shared folder, so a file an agent writes inside the sandbox can't run on the host unless the user means it to. On macOS that list missed a file type the operating system executes on open. A compromised or prompt-injected agent could leave such a file in the folder, and opening it from Claude Desktop would run commands on the Mac. Version 1.15962.0 adds it and related types. Versions from 1.1.3918 up to the fix are affected. Installs on auto-update already have the fix, and the advisory asks manual and managed deployments to update. Builds before 1.11847.5 (June 9) also shipped a Cowork VM whose guest kernel was affected by CVE-2026-43284. Combined with that, the advisory says code with elevated privileges inside the VM could trigger the file open without user action. 1.15962.0 carries both fixes. The record's package type is "other", so no dependency scanner will raise it.

LiteLLM: a newer patch release is not a fix. CVE-2026-89032 (7.7 on v3.1, 8.7 on v4), filed by VulnCheck, says the proxy's semantic cache didn't keep tenants apart. A user with a valid virtual key could receive another tenant's cached responses, including cached tool calls that an agent front end might run under the victim's credentials. It applies only to proxies with semantic caching turned on and more than one tenant behind them. The fix (PR 39590, merged September 4) first shipped in 1.101.0-rc.1 and is in 1.101.0 (September 15) and later. LiteLLM also maintains older lines, and it published 1.100.3, 1.99.4 and 1.98.1 yesterday. At all three tags the cache's tenant-scope lookup still lacks the change, so a release dated yesterday can still be affected. Move shared proxies to 1.101.0 or later, or turn semantic caching off on them. The same PR adds an opt-in semantic_cache_scope: end_user setting that isolates end users who share one key; the default is key.

mcp-remote: now scored. CISA's enrichment scored two more of Thursday's five CVEs yesterday: CVE-2026-51994 at 9.1 and CVE-2026-51997 at 8.8, next to the 7.5 already on CVE-2026-51995. Nothing else moved. 0.14.3 is still current, there has been no commit since that tag on September 21, and no release names the CVEs. The control from yesterday stands.

Also landed. @payloadcms/storage-vercel-blob (108,000 downloads a week) published GHSA-mc8m-rr6c-r5qr (5.3 on v4) yesterday. With client uploads enabled, upload access didn't follow the collection's access rules. It is fixed in 3.90.0 (September 18), so if you use that adapter with client uploads, the Payload floor is 3.90.0 rather than yesterday's 3.88.0. Until then, disable client uploads. Khoj, the self-hosted AI assistant (37,500 stars), has GHSA-62mm-xwmv-crhg (8.7 on v4), an unauthenticated file read that affects only 2.0.0-beta.23 and beta.24. It was fixed in beta.25 in February, and stable 1.42.10 is outside the range.

A correction on knowns. From September 9 to 11 this digest kept printing 0.30.0 as its floor, after the project had published six more repository advisories on September 9 that we never swept. Two are fixed in 0.31.0 and 0.32.0, and four, two of them critical, affect 0.33.0 with no fix declared. The floor is 0.32.0. The 0.34.0 release on September 22 sits above those ranges, but its notes list a Swift language adapter and no security fixes, so treat it as affected. Yesterday GitHub withdrew two duplicate knowns records and kept CVE-2026-86439 (8.8, fixed 0.30.0). One of the withdrawn duplicates carried the 0.31.0 fix, and none of the September 9 advisories is in the global database, so scanners now report 0.30.0. It has 235 downloads a week.

Paperwork your scanner may raise: smolagents CVE-2025-9959 (7.6) is a 2025 sandbox-escape record that GitHub re-imported after an NVD edit; it was fixed in 1.21.0 in August 2025. langchain4j CVE-2026-97869 (4.1) is a VulDB record for a July 29 fix that applies only with opt-in AgenticScope persistence. On the .NET side, the NuGet package CliInvoke has two 8.4 advisories for argument and command injection in its runner factory and its Cmd/PowerShell wrappers. They are fixed in 2.8.5, 2.9.4, 2.10.5 and the 3.0 betas, and it has 16,000 lifetime downloads.

Standing items. vLLM 0.30.0 is still the newest release, and all nine of its open fix PRs are still unmerged, including the six for the September 22 KV-transfer CVEs. SGLang is still v0.5.20, FalkorDB is still v4.20.7 on the C engine, and Tencent BrowserSkill's issue 273 is still open with no commits to the daemon's WebSocket handler. mcp-atlassian is still 0.23.1, with GHSA-5j8j-256g-vvp5 still repository-only. Angular's GHSA-ff3f-86qr-9cv3 and Payload's GHSA-v49j-62m6-pgrr still return 404 in GitHub's database. Chroma 1.5.9, gray-matter 4.0.3, Kotaemon v0.12.0 and mcp-fetch 1.6.3 are unchanged.

On the Microsoft side there is nothing to apply. Friday's revision of the September document touched five .NET and ASP.NET Core entries, and all five were KB-link updates to their tables. .NET 10.0.12, 9.0.20 and 8.0.31 are still the current security releases, and PrimeNG is still 22.1.1.

* * *

Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.

Elsewhere in this issue

3 more
  1. 01

    News

    Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch

    Oct 4, 2026

  2. 02

    The Patch

    The Patch — October 4, 2026

    Oct 4, 2026

  3. 03

    News

    The people who talk to the auditors — OpenAI fires three safety researchers for the kind of talking the auditors were set up to hear

    Oct 3, 2026

Letters

Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.